Threat Intelligence

AI Tool Flaw Let Malicious Models Run Hidden Code

Dark Reading · 30 Sept 2026
Key Takeaway If your business uses AI development tools, ensure they are updated to the latest patched version and avoid enabling settings like trust_remote_code unless the source is fully trusted.

Security researchers identified a flaw in Unsloth Studio, a tool used to inspect and work with AI models, that allowed specially crafted malicious models to execute arbitrary Python code on a user's machine. The issue was linked to a setting called trust_remote_code, which, when enabled, allowed code embedded in a model to run automatically during what should have been a routine inspection process.

This type of flaw is particularly concerning because it turns a normally safe action, simply examining or loading a model, into a potential point of compromise. Attackers could exploit this by distributing tampered AI models designed to trigger malicious code execution as soon as they are opened for review. The vulnerability has since been patched by the developers.

Businesses increasingly rely on third party AI models and tools as part of their operations, and this case highlights that the software used to manage them can carry its own risks. Even tools built for developers and technical teams need to be kept up to date and configured carefully.

AI security vulnerability software patch
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.